External risk intelligence

Zimbra Stored XSS via Forged Share Notification

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-93642

Zimbra is a widely deployed enterprise email and collaboration platform designed to be accessed via public-facing web portals. Because it serves as an internet-exposed mail client and identity interface, its web-based features, including share notifications, are inherently accessible and typically exposed to the public internet by design in normal operations.

Cross-site Scripting

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Zimbra Modern that could allow an unauthenticated sender to forge a share notification. If a recipient clicks an "Accept Share" link within this forged notification, it could trigger a cross-site scripting attack, potentially granting the attacker access to the victim's mailbox data and allowing them to act on behalf of the victim.

  • Forged links can steal mailbox access.
  • Widespread email platform, high exposure risk.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could send a specially crafted email that appears to be a legitimate share notification to a Zimbra user. If the recipient clicks the "Accept Share" link within this forged notification, a stored cross-site scripting vulnerability would be triggered. This could allow the attacker to access the victim's mailbox data or perform actions on their behalf.

  • Unauthenticated sender can forge notification.
  • Recipient clicks "Accept Share" link.
  • Attacker accesses mailbox data.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated sender could craft a malicious share notification. When a user clicks "Accept Share" within the Zimbra Modern interface, this could trigger a stored cross-site scripting (XSS) vulnerability. This might allow an attacker to access the victim's mailbox data and perform actions on their behalf.

  • Mailbox data and user sessions.
  • When a signed-in user accepts a forged share.
  • Unauthorized access to sensitive information.

Operational Fix

Recommended remediation, mitigation, and detection steps

Zimbra Modern administrators and the security team are likely responsible for addressing this vulnerability. The first practical step is to identify all Zimbra Modern instances, determine their exposure, and confirm business criticality. Once accountable owners are identified, remediation or risk reduction planning can commence.

  • Application and security teams own remediation.
  • Verify external access and business impact.
  • Plan based on risk and operational capacity.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Zimbra Modern platform?

Zimbra Modern is an enterprise-grade email and collaboration suite that provides users with a web-based interface for managing messages, calendars, and shared data. It is commonly deployed as a centralized communication hub, allowing teams to securely share resources and collaborate on documents within a private or organizational network environment.

What does CVE-2026-93642 mean for security?

This vulnerability is classified as Stored Cross-Site Scripting (CWE-79). It means that an attacker can inject malicious code into the Zimbra platform by mimicking a legitimate file or folder share notification. When the software stores and later executes this unauthorized code within a user's browser, it allows the attacker to bypass normal security controls and interact with the mailbox as if they were the legitimate user.

How is this XSS vulnerability triggered?

The attack requires a specific action from a signed-in user: clicking the 'Accept Share' link contained within a forged notification. Simply receiving the malicious email or notification does not trigger the vulnerability. The security flaw is only activated when the recipient interacts with the crafted element, which then executes the stored script within the context of their active session.

Is my Zimbra instance at risk?

According to Halo Surface Signal, Zimbra is a platform frequently deployed with public-facing web portals to support remote access. Because the web interface is often exposed to the internet to ensure users can reach their mail, the attack surface for this vulnerability is typically high. Instances that are fully isolated from the internet face a significantly lower risk of receiving these external forged notifications.

What should I do if I run Zimbra?

Your initial priority should be to catalog all running instances of Zimbra Modern within your environment to understand your total footprint. Once identified, evaluate which systems are accessible from the internet versus those confined to internal networks. Coordinate with your application and security teams to prioritize these systems for investigation and prepare for necessary security updates provided by the vendor.

References